{"cve":"CVE-2026-44756","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"KRNL64NUC 7.22"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.22EXT"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"KRNL64UC 7.22"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.53"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"8.04"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"WEBDISP 9.16"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"9.18"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"9.19"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"9.20"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"KERNEL 7.22"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.54"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.77"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.89"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"7.93"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"9.16"}}],"enrichment":{"confidence":100.0,"confidence_source":"cna","scores":[{"score":100.0,"source":"cna"}]},"original":{"product":"SAP Extended Passport (EPP) Processing","source":"cna","vendor":"SAP_SE"},"product":"sap_extended_passport_(epp)_processing","vendor":"sap_se"}],"created":"2026-09-08T01:30:06.561955+00:00","updated":"2026-09-08T20:36:26.525673+00:00","vendors":["sap_se","sap_se$PRODUCT$sap_extended_passport_(epp)_processing"]},"epss":{"score":0.00367},"mitre":{"cpes":[],"created":"2026-09-08T00:10:16.283000+00:00","description":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/44xxx/CVE-2026-44756.json","references":["https://me.sap.com/notes/3747649","https://url.sap/sapsecuritypatchday"],"title":"Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing","updated":"2026-09-22T20:07:26.300000+00:00","vendors":[],"weaknesses":["CWE-120"]},"nvd":{"cpes":[],"created":"2026-09-08T01:17:30.840000+00:00","description":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10.0,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-44756.json","references":["http://seclists.org/fulldisclosure/2026/Sep/65","https://me.sap.com/notes/3747649","https://url.sap/sapsecuritypatchday"],"title":null,"updated":"2026-09-22T21:17:30.593000+00:00","vendors":[],"weaknesses":["CWE-120"]},"opencve":{"changes":[{"created":"2026-09-08T00:45:00+00:00","data":[{"details":{"new":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.","old":null},"type":"description"},{"details":{"new":"Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing","old":null},"type":"title"},{"details":{"added":["CWE-120"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://me.sap.com/notes/3747649","https://url.sap/sapsecuritypatchday"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"94df94c3-0ae7-4c31-8a20-9d00fbecfafb"},{"created":"2026-09-08T13:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"0bd6e474-d5fa-4ae6-94df-42d661eae769"},{"created":"2026-09-08T21:00:00+00:00","data":[{"details":["sap_se","sap_se$PRODUCT$sap_extended_passport_(epp)_processing"],"type":"first_time"},{"details":{"added":["sap_se","sap_se$PRODUCT$sap_extended_passport_(epp)_processing"],"removed":[]},"type":"vendors"}],"id":"39eb9820-7d12-4fcc-9235-a940257384fd"},{"created":"2026-09-22T21:30:00+00:00","data":[{"details":{"added":["http://seclists.org/fulldisclosure/2026/Sep/65"],"removed":[]},"type":"references"}],"id":"83e7778d-457c-4d1a-bc43-cd3463d6c1e6"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-08T00:10:16.283000+00:00","provider":"mitre"},"description":{"data":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00367},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://seclists.org/fulldisclosure/2026/Sep/65","https://me.sap.com/notes/3747649","https://url.sap/sapsecuritypatchday"],"providers":["mitre","nvd"]},"title":{"data":"Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing","provider":"mitre"},"updated":{"data":"2026-09-22T21:17:30.593000+00:00","provider":"nvd"},"vendors":{"data":["sap_se","sap_se$PRODUCT$sap_extended_passport_(epp)_processing"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-120"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-08T00:10:16.283000+00:00","description":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing","updated":"2026-09-08T12:42:12.833000+00:00","vendors":[],"vulnrichment_repo_path":"2026/44xxx/CVE-2026-44756.json","weaknesses":[]}}